Executive Summary
Msg & data rates disclosure tells consumers that standard carrier messaging and data charges may apply when they opt into business SMS. It appears beside opt-in actions, in confirmation texts, HELP replies, and program terms. Reviewers of 10DLC Campaigns and consumers alike look for this language. Missing or hidden rate disclosures create packaging friction and erode trust—even though the exact carrier charge depends on the subscriber’s plan.
Short answer: Include clear “Msg & data rates may apply” (or equivalent) on opt-in surfaces, recurring program confirmations, and HELP paths. Pair it with frequency language and STOP/HELP instructions. Do not invent specific dollar amounts for “standard rates.”
Who This Is For / Who It Is Not For
Who this is for
- Teams writing web, POS, and keyword opt-ins
- CSP customers preparing Campaign message flows
- Support teams configuring HELP auto-replies
Who this is not for
- Carriers setting retail SMS tariffs
- Anyone promising “free SMS forever” without legal review
Definitions
| Term | Meaning |
|---|---|
| Msg & data rates may apply | Common consumer disclosure that carrier charges may apply |
| Frequency disclosure | How often messages will be sent |
| HELP reply | Automated response to HELP keyword |
| Program terms | Hosted SMS terms page |
Where to Place the Disclosure
| Surface | Include rate disclosure? | Also include |
|---|---|---|
| Web/POS opt-in near checkbox | Yes | Frequency, STOP/HELP, brand, purpose |
| Keyword join ads | Yes | Brand, program, STOP/HELP |
| Opt-in confirmation SMS | Yes (common expectation) | Brand, STOP, frequency |
| HELP auto-reply | Yes | Support contact, STOP |
| Privacy policy / SMS terms | Yes | Full program rules |
| Every marketing blast | Optional but brand ID + STOP still required | Avoid stuffing every blast with essays |
CTIA short-code monitoring materials historically emphasize confirmation content including message-and-data-rates language for recurring programs (except certain free-to-end-user designs). Apply the spirit to 10DLC opt-ins even though handbooks target short codes.
Example Wording (Educational)
“Msg & data rates may apply. Message frequency varies. Reply STOP to opt out, HELP for help.”
“Standard message and data rates may apply according to your mobile plan.”
Do not invent a dollar figure. Plans differ.
Decision Framework
- Audit every opt-in surface for missing rate language.
- Align confirmation and HELP templates.
- Mirror language in SMS terms page.
- Update Campaign message flow text to mention disclosures shown.
- Screenshot surfaces for registration evidence.
- Re-audit after UX redesigns.
Risk and Failure Modes
| Risk | Mitigation |
|---|---|
| Disclosure in footer only | Place near the action |
| Claiming SMS is always free | Remove unless truly free-to-end-user and counsel-approved |
| Rate disclosure without STOP | Add STOP/HELP |
| Inconsistency across languages | Translate carefully |
Implementation Checklist
| Step | Owner | Artifact |
|---|---|---|
| Surface inventory | Marketing | Checklist |
| Copy approval | Legal | Approved strings |
| HELP/STOP config | Messaging | Reply templates |
| Terms page update | Web | Live URL |
| Screenshot pack | Compliance | Evidence zip |
Soft CTA
Compare your live pages against MyTCRPlus disclosure guidance at msg & data rates disclosure and preflight with tools.
FAQ
Is “Msg & data rates may apply” legally required wording?
It is a widely expected consumer disclosure in messaging programs; include it unless counsel designs an alternative for a true free-to-end-user program.
Do I need it on transactional texts?
Best practice is to disclose at opt-in for the program; confirmations often repeat it.
Can I say SMS is free?
Only if accurate for the end user and approved by counsel—carrier plans still may charge.
Does disclosure replace consent?
No.
Where do reviewers look?
Opt-in UI, message flow narrative, samples, and terms URLs.
Key Takeaways
- Place rate disclosures next to opt-in actions.
- Pair with frequency and STOP/HELP.
- Do not invent dollar amounts.
- Keep HELP replies consistent.
- Screenshot evidence for Campaign packets.
Extended Implementation Playbook
This playbook converts the principles in the article into a sequenced project plan your team can execute without guessing.
Phase 0 — Discovery (week 1)
Interview every team that can trigger an SMS. Export template lists from each vendor. Classify each template as marketing, informational, or conversational care. Identify which legal entity owns each sending number. Capture current consent language screenshots. Produce a gap list: unregistered numbers, missing privacy URLs, bundled checkboxes, and vendors without STOP webhooks.
Phase 1 — Foundations (weeks 2–3)
Publish or repair website privacy and SMS terms. Align legal name and tax ID documents for Brand registration. Select Brand type with your CSP based on expected volume—without inventing universal fee or MPS figures. Draft Campaign descriptions using the who/who/why test. Write message flows that narrate the real opt-in path. Prepare sample messages with brand identification and STOP language.
Phase 2 — Registration (weeks 3–5)
Submit Brand; resolve verification issues immediately. Submit Campaign(s); respond to rejection reasons with packaging fixes rather than argument. Associate numbers only after approval. Configure HELP/STOP replies and test from multiple carrier handsets. Confirm CSP-stated throughput for planning.
Phase 3 — Controls (weeks 5–6)
Connect all vendors to a central suppression list. Enforce template governance so production copy cannot drift silently from registered samples. Train staff with send permissions. Stand up weekly metrics: delivery failures, STOP rate, HELP volume, and exception counts. Create an incident severity model for post-STOP sends and unregistered traffic.
Phase 4 — Scale (ongoing)
Expand locations or programs only after soft-launch metrics stabilize. Revisit packaging when adding loyalty vendors, franchise markets, or new promo calendars. Schedule quarterly counsel review for consent language and state overlays. Re-verify Brand data after mergers, rebrands, or address changes.
RACI snapshot
| Activity | Compliance | Marketing | Engineering | Counsel | CSP admin |
|---|---|---|---|---|---|
| Consent copy | A | R | C | C | I |
| Campaign packaging | R | C | I | C | A |
| Number association | C | I | R | I | A |
| STOP propagation | A | I | R | I | C |
| Incident response | A | C | R | C | C |
Evidence you should be able to produce in 24 hours
- Brand ID and Campaign IDs
- Live privacy and SMS terms URLs
- Opt-in screenshot with version date
- Consent record sample with timestamp and disclosure hash
- STOP log showing suppression timestamps across systems
- Current sample message library
If you cannot produce these, you are not ready for aggressive growth sends—regardless of how polished the marketing calendar looks.
Executive talking points
- Registration identifies us to carriers; it does not create recipient consent.
- Throughput and fees are provider-specific; we will not quote invented industry averages.
- STOP must work everywhere we can send, not only in the primary ESP.
- Template drift is a first-class risk and will be gated like a production change.
Adapt timelines to your CSP review queues. This playbook is operational guidance, not a guarantee of approval timelines or legal safe harbor.
Extended Implementation Playbook
This playbook converts the principles in the article into a sequenced project plan your team can execute without guessing.
Phase 0 — Discovery (week 1)
Interview every team that can trigger an SMS. Export template lists from each vendor. Classify each template as marketing, informational, or conversational care. Identify which legal entity owns each sending number. Capture current consent language screenshots. Produce a gap list: unregistered numbers, missing privacy URLs, bundled checkboxes, and vendors without STOP webhooks.
Phase 1 — Foundations (weeks 2–3)
Publish or repair website privacy and SMS terms. Align legal name and tax ID documents for Brand registration. Select Brand type with your CSP based on expected volume—without inventing universal fee or MPS figures. Draft Campaign descriptions using the who/who/why test. Write message flows that narrate the real opt-in path. Prepare sample messages with brand identification and STOP language.
Phase 2 — Registration (weeks 3–5)
Submit Brand; resolve verification issues immediately. Submit Campaign(s); respond to rejection reasons with packaging fixes rather than argument. Associate numbers only after approval. Configure HELP/STOP replies and test from multiple carrier handsets. Confirm CSP-stated throughput for planning.
Phase 3 — Controls (weeks 5–6)
Connect all vendors to a central suppression list. Enforce template governance so production copy cannot drift silently from registered samples. Train staff with send permissions. Stand up weekly metrics: delivery failures, STOP rate, HELP volume, and exception counts. Create an incident severity model for post-STOP sends and unregistered traffic.
Phase 4 — Scale (ongoing)
Expand locations or programs only after soft-launch metrics stabilize. Revisit packaging when adding loyalty vendors, franchise markets, or new promo calendars. Schedule quarterly counsel review for consent language and state overlays. Re-verify Brand data after mergers, rebrands, or address changes.
RACI snapshot
| Activity | Compliance | Marketing | Engineering | Counsel | CSP admin |
|---|---|---|---|---|---|
| Consent copy | A | R | C | C | I |
| Campaign packaging | R | C | I | C | A |
| Number association | C | I | R | I | A |
| STOP propagation | A | I | R | I | C |
| Incident response | A | C | R | C | C |
Evidence you should be able to produce in 24 hours
- Brand ID and Campaign IDs
- Live privacy and SMS terms URLs
- Opt-in screenshot with version date
- Consent record sample with timestamp and disclosure hash
- STOP log showing suppression timestamps across systems
- Current sample message library
If you cannot produce these, you are not ready for aggressive growth sends—regardless of how polished the marketing calendar looks.
Executive talking points
- Registration identifies us to carriers; it does not create recipient consent.
- Throughput and fees are provider-specific; we will not quote invented industry averages.
- STOP must work everywhere we can send, not only in the primary ESP.
- Template drift is a first-class risk and will be gated like a production change.
Adapt timelines to your CSP review queues. This playbook is operational guidance, not a guarantee of approval timelines or legal safe harbor.
Extended Implementation Playbook
This playbook converts the principles in the article into a sequenced project plan your team can execute without guessing.
Phase 0 — Discovery (week 1)
Interview every team that can trigger an SMS. Export template lists from each vendor. Classify each template as marketing, informational, or conversational care. Identify which legal entity owns each sending number. Capture current consent language screenshots. Produce a gap list: unregistered numbers, missing privacy URLs, bundled checkboxes, and vendors without STOP webhooks.
Phase 1 — Foundations (weeks 2–3)
Publish or repair website privacy and SMS terms. Align legal name and tax ID documents for Brand registration. Select Brand type with your CSP based on expected volume—without inventing universal fee or MPS figures. Draft Campaign descriptions using the who/who/why test. Write message flows that narrate the real opt-in path. Prepare sample messages with brand identification and STOP language.
Phase 2 — Registration (weeks 3–5)
Submit Brand; resolve verification issues immediately. Submit Campaign(s); respond to rejection reasons with packaging fixes rather than argument. Associate numbers only after approval. Configure HELP/STOP replies and test from multiple carrier handsets. Confirm CSP-stated throughput for planning.
Phase 3 — Controls (weeks 5–6)
Connect all vendors to a central suppression list. Enforce template governance so production copy cannot drift silently from registered samples. Train staff with send permissions. Stand up weekly metrics: delivery failures, STOP rate, HELP volume, and exception counts. Create an incident severity model for post-STOP sends and unregistered traffic.
Phase 4 — Scale (ongoing)
Expand locations or programs only after soft-launch metrics stabilize. Revisit packaging when adding loyalty vendors, franchise markets, or new promo calendars. Schedule quarterly counsel review for consent language and state overlays. Re-verify Brand data after mergers, rebrands, or address changes.
RACI snapshot
| Activity | Compliance | Marketing | Engineering | Counsel | CSP admin |
|---|---|---|---|---|---|
| Consent copy | A | R | C | C | I |
| Campaign packaging | R | C | I | C | A |
| Number association | C | I | R | I | A |
| STOP propagation | A | I | R | I | C |
| Incident response | A | C | R | C | C |
Evidence you should be able to produce in 24 hours
- Brand ID and Campaign IDs
- Live privacy and SMS terms URLs
- Opt-in screenshot with version date
- Consent record sample with timestamp and disclosure hash
- STOP log showing suppression timestamps across systems
- Current sample message library
If you cannot produce these, you are not ready for aggressive growth sends—regardless of how polished the marketing calendar looks.
Executive talking points
- Registration identifies us to carriers; it does not create recipient consent.
- Throughput and fees are provider-specific; we will not quote invented industry averages.
- STOP must work everywhere we can send, not only in the primary ESP.
- Template drift is a first-class risk and will be gated like a production change.
Adapt timelines to your CSP review queues. This playbook is operational guidance, not a guarantee of approval timelines or legal safe harbor.
Extended Implementation Playbook
This playbook converts the principles in the article into a sequenced project plan your team can execute without guessing.
Phase 0 — Discovery (week 1)
Interview every team that can trigger an SMS. Export template lists from each vendor. Classify each template as marketing, informational, or conversational care. Identify which legal entity owns each sending number. Capture current consent language screenshots. Produce a gap list: unregistered numbers, missing privacy URLs, bundled checkboxes, and vendors without STOP webhooks.
Phase 1 — Foundations (weeks 2–3)
Publish or repair website privacy and SMS terms. Align legal name and tax ID documents for Brand registration. Select Brand type with your CSP based on expected volume—without inventing universal fee or MPS figures. Draft Campaign descriptions using the who/who/why test. Write message flows that narrate the real opt-in path. Prepare sample messages with brand identification and STOP language.
Phase 2 — Registration (weeks 3–5)
Submit Brand; resolve verification issues immediately. Submit Campaign(s); respond to rejection reasons with packaging fixes rather than argument. Associate numbers only after approval. Configure HELP/STOP replies and test from multiple carrier handsets. Confirm CSP-stated throughput for planning.
Phase 3 — Controls (weeks 5–6)
Connect all vendors to a central suppression list. Enforce template governance so production copy cannot drift silently from registered samples. Train staff with send permissions. Stand up weekly metrics: delivery failures, STOP rate, HELP volume, and exception counts. Create an incident severity model for post-STOP sends and unregistered traffic.
Phase 4 — Scale (ongoing)
Expand locations or programs only after soft-launch metrics stabilize. Revisit packaging when adding loyalty vendors, franchise markets, or new promo calendars. Schedule quarterly counsel review for consent language and state overlays. Re-verify Brand data after mergers, rebrands, or address changes.
RACI snapshot
| Activity | Compliance | Marketing | Engineering | Counsel | CSP admin |
|---|---|---|---|---|---|
| Consent copy | A | R | C | C | I |
| Campaign packaging | R | C | I | C | A |
| Number association | C | I | R | I | A |
| STOP propagation | A | I | R | I | C |
| Incident response | A | C | R | C | C |
Evidence you should be able to produce in 24 hours
- Brand ID and Campaign IDs
- Live privacy and SMS terms URLs
- Opt-in screenshot with version date
- Consent record sample with timestamp and disclosure hash
- STOP log showing suppression timestamps across systems
- Current sample message library
If you cannot produce these, you are not ready for aggressive growth sends—regardless of how polished the marketing calendar looks.
Executive talking points
- Registration identifies us to carriers; it does not create recipient consent.
- Throughput and fees are provider-specific; we will not quote invented industry averages.
- STOP must work everywhere we can send, not only in the primary ESP.
- Template drift is a first-class risk and will be gated like a production change.
Adapt timelines to your CSP review queues. This playbook is operational guidance, not a guarantee of approval timelines or legal safe harbor.
Disclaimer
Informational only—not legal advice.